Courseiva
Perform threat hunting →easyMultiple Choice

Credential Dumping Detection: Event ID and Table

You are threat hunting for credential dumping activity. Which Windows event ID is commonly associated with the use of tools like Mimikatz?

Quick Answer

The correct answer is Windows Event ID 4688 (Process Creation). This event logs every new process spawned on the system, including the execution of tools like Mimikatz, which creates a process such as mimikatz.exe. The 4688 event captures critical details like the command line, parent process, and user context, making it essential for credential dumping detection. On the Microsoft Security Operations Analyst SC-200 exam, this tests your ability to correlate process creation events with known attack tools, often appearing in threat hunting scenarios where you must distinguish legitimate processes from malicious ones. A common trap is focusing on Event ID 4624 (Logon) or 4672 (Special Privileges), which log authentication rather than process execution. For a memory tip, remember “4688 for the gate” — every tool that runs must pass through a process creation gate, and Mimikatz is no exception.

⚠ Common exam trap

Microsoft often tests the misconception that credential dumping is tied to authentication events (like 4624 or 4768), but the key indicator is the process creation event (4688) that captures the execution of the dumping tool itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

4688 (Process Creation)

Windows Event ID 4688 (Process Creation) logs every new process spawned on the system, including the execution of tools like Mimikatz. When Mimikatz runs, it creates a process (e.g., mimikatz.exe), and the 4688 event captures the command line, parent process, and user context, which are critical for detecting credential dumping activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4624 (Successful Logon)

    Why it's wrong here

    Event 4624 records a successful logon, which confirms authentication occurred but captures no process access to LSASS memory. It is tempting because credential dumping is often followed by suspicious logons, and 4624 would be the right event when correlating anomalous sign-in patterns rather than detecting the dumping technique itself.

  • ✗

    4768 (Kerberos Authentication Ticket Request)

    Why it's wrong here

    Event 4768 records a Kerberos TGT request, which occurs during normal authentication, not the memory reads Mimikatz performs against LSASS. It is tempting because Kerberos events appear in credential-theft investigations, and 4768 would be the right focus when hunting ticket-based attacks such as Kerberoasting or golden-ticket forgery.

  • ✓

    4688 (Process Creation)

    Why this is correct

    Event ID 4688 records process creation with command-line auditing enabled, capturing Mimikatz execution and its suspicious arguments. This contrasts with 4624 logons or 4672 privilege assignment, which show access but not the credential-dumping tool itself.

  • ✗

    4672 (Special Logon)

    Why it's wrong here

    Event 4672 logs special privileges assigned to a new logon, which flags privileged account activity rather than LSASS memory access by credential-dumping tools. It is tempting because Mimikatz output often includes privileged credentials, and 4672 would be the correct event when auditing administrative logons or tracking privilege escalation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A threat hunter is using Microsoft Defender XDR Advanced hunting to find evidence of credential dumping. Which table should be queried to detect use of tools like Mimikatz?

easy
  • A.CloudAppEvents
  • ✓ B.DeviceEvents
  • C.IdentityLogonEvents
  • D.EmailEvents

Why B: DeviceEvents in Microsoft Defender XDR Advanced Hunting contains process-level and device-level telemetry, including process creation events that capture command lines and parent-child process relationships. Credential dumping tools like Mimikatz execute as processes (e.g., mimikatz.exe, sekurlsa::logonpasswords) and often spawn from suspicious parents like Office apps or scripting engines, so their execution artifacts appear in DeviceEvents. Querying DeviceEvents for process creation and command-line patterns is the standard way to detect Mimikatz in Advanced Hunting.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.